Detection of TCP covert channel based on Markov model

被引:7
|
作者
Zhai, Jiangtao [1 ]
Liu, Guangjie [1 ]
Dai, Yuewei [1 ]
机构
[1] Nanjing Univ Sci & Technol, Sch Automat, Nanjing 210094, Jiangsu, Peoples R China
关键词
TCP covert channel; Markov model; Covert channel detection; MAP;
D O I
10.1007/s11235-013-9737-7
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Network covert channel is a covert communication method by hiding covert messages into overt network packets. In recent years, with the development of various hiding methods, network covert channel has become a new kind of threat for network security. The covert channel that uses the redundancies existing in TCP protocol to make hiding is called TCP covert channel. In this paper, the behaviors of TCP flows are modeled by the Markov chain composed of the states of TCP packets. And the abnormality caused by TCP covert channel is described by the difference between the overt and covert TCP transition probability matrix. The detection method based on MAP is proposed to detect the covert communication hidden in TCP flows under various applications such as HTTP, FTP, TELNET, SSH and SMTP. Experiments show that the proposed algorithm achieves better detection performance than the existing methods.
引用
收藏
页码:333 / 343
页数:11
相关论文
共 50 条
  • [31] RETRACTED: Detection of Constellation-Modulated Wireless Covert Channel Based on Adjusted CNN Model (Retracted Article)
    Huang, Shuhua
    Liu, Weiwei
    Liu, Guangjie
    Dai, Yuewei
    Bai, Huiwen
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [32] Markov Model Design of TCP Network Systems
    Xu Wenjuan
    Jing Yuanwei
    Dimirovski, Georgi M.
    PROCEEDINGS OF THE 2019 31ST CHINESE CONTROL AND DECISION CONFERENCE (CCDC 2019), 2019, : 1308 - 1312
  • [33] A Concurrent Multipath TCP and Its Markov Model
    Sarkar, Dilip
    2006 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-12, 2006, : 615 - 620
  • [34] Packet Length Covert Channel: A Detection Scheme
    Elsadig, Muawia A.
    Fadlalla, Yahia A.
    2018 1ST INTERNATIONAL CONFERENCE ON COMPUTER APPLICATIONS & INFORMATION SECURITY (ICCAIS' 2018), 2018,
  • [35] Covert Channel Detection: Machine Learning Approaches
    Elsadig, Muawia A.
    Gafar, Ahmed
    IEEE ACCESS, 2022, 10 : 38391 - 38405
  • [36] Information Transfer Model of Virtual Machine Based on Storage Covert Channel
    WANG Xiaorui
    WANG Qingxian
    GUO Yudong
    LU Jianping
    Wuhan University Journal of Natural Sciences, 2013, 18 (05) : 377 - 384
  • [37] Study on detection of covert channel in Flume system
    School of Computer, Wuhan University, Wuhan 430072, China
    不详
    Cao, H. (caohui_computer@163.com), 1600, Science Press (50):
  • [38] Covert Channel Detection Using Machine Learning
    Cavusoglu, Imge Gamze
    Alemdar, Hande
    Onur, Ertan
    2020 28TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2020,
  • [39] Covert channel detection using Information Theory
    Helouet, Loic
    Roumy, Aline
    ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, 2011, (51): : 34 - 51
  • [40] A Probability-Model-Based Approach to Detect Covert Timing Channel
    Yang, Peng
    Zhao, Hui
    Bao, Zhonggui
    2015 IEEE INTERNATIONAL CONFERENCE ON INFORMATION AND AUTOMATION, 2015, : 1043 - 1047